Skip to content

Deploy releases/k8s-manifests aae9308 - #189

Merged
themightychris merged 6 commits into
deploys/k8s-manifestsfrom
releases/k8s-manifests
Sep 8, 2026
Merged

Deploy releases/k8s-manifests aae9308#189
themightychris merged 6 commits into
deploys/k8s-manifestsfrom
releases/k8s-manifests

Conversation

@github-actions

@github-actions github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown

kubectl diff reports that applying aae9308 will change:

diff -uN /tmp/LIVE-3532408252/v1.Namespace..codeforphilly-ng /tmp/MERGED-2328355770/v1.Namespace..codeforphilly-ng
--- /tmp/LIVE-3532408252/v1.Namespace..codeforphilly-ng	2026-09-08 23:40:21.910394449 +0000
+++ /tmp/MERGED-2328355770/v1.Namespace..codeforphilly-ng	2026-09-08 23:40:31.006660088 +0000
@@ -1 +1,9 @@
-{}
+apiVersion: v1
+kind: Namespace
+metadata:
+  labels:
+    kubernetes.io/metadata.name: codeforphilly-ng
+  name: codeforphilly-ng
+spec:
+  finalizers:
+  - kubernetes

Errors/Warnings

=== Directory: ./codeforphilly-ng ===
Error from server (NotFound): namespaces "codeforphilly-ng" not found

themightychris and others added 6 commits September 8, 2026 19:12
…y.org rewrite

Stands the rewrite up in its own `codeforphilly-ng` namespace alongside the
legacy laddr app, mirroring the cfp-sandbox-cluster wiring: upstream
manifests projected from codeforphilly-ng:deploy/kustomize/base at a pinned
release tag, a per-cluster Gateway/HTTPRoute, and a kustomize lens.

Pre-cutover host is next.codeforphilly.org. Because the apex already
resolves to this cluster's Envoy gateway, cutover is a hostname move
between _gateways/code-for-philly.yaml and _gateways/codeforphilly-ng.yaml
with no DNS change; rollback is a revert.

Sealed secrets (codeforphilly-ng.secrets/) land in a follow-up commit.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RdRwHvDupRLV8GuJpYKzEr
- codeforphilly-saml: the SAML IdP key pair carried over verbatim from the
  legacy laddr `saml2` secret so Slack keeps trusting the same signing cert
  across cutover (only the SSO URL changes on the Slack side).
- codeforphilly-data-deploy-key: new read-write deploy key registered on
  CodeForPhilly/codeforphilly-data for the push daemon.
- codeforphilly-secrets: fresh JWT signing key, data remote, and the
  hot-reload bearer secret shared with sandbox so codeforphilly-data's
  notify-deployments workflow can fan out to both targets.

GitHub OAuth and Postmark credentials follow once provisioned.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RdRwHvDupRLV8GuJpYKzEr
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RdRwHvDupRLV8GuJpYKzEr
New org OAuth app "Code for Philly" (the legacy laddr app was renamed
"Code for Philly (legacy)"). Callback is registered on the apex; GitHub
accepts the pre-cutover next.codeforphilly.org subdomain against it, so no
edit is needed on cutover day.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01RdRwHvDupRLV8GuJpYKzEr
feat(codeforphilly-ng): production deployment of the codeforphilly.org rewrite
Source-holobranch: k8s-manifests-github
Source-commit: 7b6af34
Source: 7b6af34
@themightychris
themightychris merged commit 31c9c75 into deploys/k8s-manifests Sep 8, 2026
1 check passed
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Author

kubectl apply output (excluding unchanged) for 31c9c75 was:

customresourcedefinition.apiextensions.k8s.io/backends.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/backendtlspolicies.gateway.networking.k8s.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/backendtrafficpolicies.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/certificaterequests.cert-manager.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/certificates.cert-manager.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/challenges.acme.cert-manager.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/clienttrafficpolicies.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/clusterissuers.cert-manager.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/envoyextensionpolicies.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/envoypatchpolicies.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/envoyproxies.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/gatewayclasses.gateway.networking.k8s.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/gateways.gateway.networking.k8s.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/grpcroutes.gateway.networking.k8s.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/httproutefilters.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/httproutes.gateway.networking.k8s.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/issuers.cert-manager.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/listenersets.gateway.networking.k8s.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/orders.acme.cert-manager.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/referencegrants.gateway.networking.k8s.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/sealedsecrets.bitnami.com serverside-applied
customresourcedefinition.apiextensions.k8s.io/securitypolicies.gateway.envoyproxy.io serverside-applied
customresourcedefinition.apiextensions.k8s.io/tlsroutes.gateway.networking.k8s.io serverside-applied
clusterrole.rbac.authorization.k8s.io/envoy-gateway-gateway-helm-envoy-gateway-role configured
clusterrole.rbac.authorization.k8s.io/grafana-clusterrole configured
clusterrole.rbac.authorization.k8s.io/prometheus-alertmanager configured
clusterrole.rbac.authorization.k8s.io/prometheus-pushgateway configured
clusterrolebinding.rbac.authorization.k8s.io/sealed-secrets configured
mutatingwebhookconfiguration.admissionregistration.k8s.io/cert-manager-webhook configured
mutatingwebhookconfiguration.admissionregistration.k8s.io/envoy-gateway-topology-injector.envoy-gateway-system configured
namespace/codeforphilly-ng created
validatingadmissionpolicy.admissionregistration.k8s.io/safe-upgrades.gateway.networking.k8s.io configured
validatingadmissionpolicybinding.admissionregistration.k8s.io/safe-upgrades.gateway.networking.k8s.io configured
validatingwebhookconfiguration.admissionregistration.k8s.io/cert-manager-webhook configured
secret/regcred created
gateway.gateway.networking.k8s.io/balancer configured
httproute.gateway.networking.k8s.io/balancer configured
gateway.gateway.networking.k8s.io/chime configured
httproute.gateway.networking.k8s.io/chime configured
gateway.gateway.networking.k8s.io/choose-native-plants configured
httproute.gateway.networking.k8s.io/choose-native-plants configured
deployment.apps/code-for-philly configured
gateway.gateway.networking.k8s.io/code-for-philly configured
httproute.gateway.networking.k8s.io/code-for-philly configured
configmap/codeforphilly-env created
deployment.apps/codeforphilly created
gateway.gateway.networking.k8s.io/codeforphilly created
httproute.gateway.networking.k8s.io/codeforphilly created
persistentvolumeclaim/codeforphilly-private created
sealedsecret.bitnami.com/codeforphilly-data-deploy-key created
sealedsecret.bitnami.com/codeforphilly-saml created
sealedsecret.bitnami.com/codeforphilly-secrets created
service/codeforphilly created
serviceaccount/codeforphilly created
gateway.gateway.networking.k8s.io/echo-http configured
httproute.gateway.networking.k8s.io/echo-http configured
deployment.apps/envoy-gateway configured
httproute.gateway.networking.k8s.io/http-redirect configured
configmap/grafana-dashboards-default configured
deployment.apps/grafana configured
gateway.gateway.networking.k8s.io/grafana configured
httproute.gateway.networking.k8s.io/grafana configured
deployment.apps/metrics-server configured
secret/promtail configured
statefulset.apps/loki configured
deployment.apps/prometheus-alertmanager configured
deployment.apps/prometheus-kube-state-metrics configured
deployment.apps/prometheus-pushgateway configured
deployment.apps/prometheus-server configured
serviceaccount/prometheus-kube-state-metrics configured
deployment.apps/sealed-secrets configured
gateway.gateway.networking.k8s.io/sealed-secrets configured
httproute.gateway.networking.k8s.io/sealed-secrets configured
rolebinding.rbac.authorization.k8s.io/sealed-secrets-key-admin configured
service/sealed-secrets configured
gateway.gateway.networking.k8s.io/third-places configured
httproute.gateway.networking.k8s.io/third-places configured
statefulset.apps/third-places-postgresql configured
gateway.gateway.networking.k8s.io/vaultwarden configured
httproute.gateway.networking.k8s.io/bitwarden-redirect configured
httproute.gateway.networking.k8s.io/vaultwarden configured
statefulset.apps/vaultwarden-postgresql configured

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant